Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2016-5385

Disclosure Date: July 19, 2016
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application’s outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv(‘HTTP_PROXY’) call or (2) a CGI configuration of PHP, aka an “httpoxy” issue.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.1 High
Impact Score:
5.9
Exploitability Score:
2.2
Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • debian,
  • drupal,
  • fedoraproject,
  • hp,
  • opensuse,
  • oracle,
  • php,
  • redhat

Products

  • communications user data repository 10.0.0,
  • communications user data repository 10.0.1,
  • communications user data repository 12.0.0,
  • debian linux 8.0,
  • drupal,
  • enterprise linux desktop 6.0,
  • enterprise linux server 6.0,
  • enterprise linux workstation 6.0,
  • enterprise manager ops center 12.2.2,
  • enterprise manager ops center 12.3.2,
  • fedora 23,
  • fedora 24,
  • leap 42.1,
  • linux 6,
  • linux 7,
  • php,
  • storeever msl6480 tape library firmware,
  • system management homepage

References

Advisory

Additional Info

Technical Analysis